Vulnerability record · CVE-2023-20888 · published 7 June 2023
CVE-2023-20888: VMware Aria Operations for Networks authenticated deserialization RCE
Vmware · Vrealize Network Insight
VMware Aria Operations for Networks (vRealize Network Insight) contains a deserialization of untrusted data flaw (CWE-502). An attacker with valid 'member' role credentials and network access can trigger a deserialization attack that leads to remote code execution. The flaw matters because it turns low-privilege authenticated access into full code execution on a management platform.
Description
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityAuthenticated network-reachable RCE with high CVSS (8.8) and very high EPSS, though it requires valid low-privilege credentials and no KEV listing or confirmed public exploit.
What it is
VMware Aria Operations for Networks (vRealize Network Insight) contains a deserialization of untrusted data flaw (CWE-502). An attacker with valid 'member' role credentials and network access can trigger a deserialization attack that leads to remote code execution. The flaw matters because it turns low-privilege authenticated access into full code execution on a management platform.
Impact
An attacker gains remote code execution on the affected appliance, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the Aria Operations for Networks deployment and any data or credentials it holds.
Attack surface
Reached over the network (AV:N) by an authenticated user holding valid 'member' role credentials; no user interaction is required (UI:N). The attack requires low privileges (PR:L) but no special network position beyond connectivity to the product.
Exploitation
Not listed in CISA KEV and no ransomware usage documented. EPSS is very high (0.82282, 99.6th percentile), and the only references are the vendor advisory tagged Patch and Vendor Advisory, so no public exploit code is confirmed in this record.
What to do
- Apply the patch from VMware advisory VMSA-2023-0012 as the first action.
- Restrict network access to Aria Operations for Networks management interfaces to trusted networks only.
- Review and minimize accounts holding the 'member' role; remove or disable unused accounts.
- Rotate credentials and secrets that were accessible to any account that may have been abused.
- Monitor for unexpected process execution or outbound connections from the appliance after patching.
Detection
- Alert on unusual child processes or command execution spawned by the Aria Operations for Networks application or its Java runtime.
- Monitor authentication logs for 'member' role logins from new or unexpected source IPs.
- Watch for anomalous outbound network connections from the appliance to untrusted hosts.
- Correlate deserialization-related errors or crashes in application logs with subsequent process activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2023-0012.html | PatchVendor Advisory |
| https://www.vmware.com/security/advisories/VMSA-2023-0012.html | PatchVendor Advisory |
Track CVE-2023-20888 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-20888), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.